Patient identity
Full legal name and unique identifier such as medical record number or date of birth to unambiguously link authorization to a specific patient.
Clear, complete HIPAA authorizations protect patient privacy, reduce legal risk, and ensure lawful disclosures of protected health information. Properly executed forms support audits, breach responses, and consistent data-sharing between providers and business associates.
Covered entities, health systems, clinics, and business associates generally prepare HIPAA authorization forms before sharing patient information or responding to requests.
Individuals sign or revoke authorizations; designated representatives sign when permitted by state law or patient instruction.
Full legal name and unique identifier such as medical record number or date of birth to unambiguously link authorization to a specific patient.
A precise description of the information to be disclosed (e.g., 'clinic notes from 01/01/2020–12/31/2020' or 'lab results for hepatitis C').
The specific purpose or need for disclosure (treatment, payment, legal, research) so the scope is limited and documented.
Name and contact of the person or organization authorized to receive PHI, including address or secure transmission instructions.
A clear expiration date or specific event (e.g., 'until completion of claim') after which the authorization is no longer effective.
Signature of the individual or authorized representative and signature date; include statement of authority when signed by representative.
| Field | Configuration |
|---|---|
| Authentication level | Use at least email plus SMS or ID verification for high-sensitivity disclosures. |
| Document retention | Set automated retention to 6 years to align with HIPAA 45 CFR §164.530(j). |
| Audit trail | Enable IP, timestamp, and signer attribution logging for every signature event. |
| Access controls | Limit who can view or resend authorizations using role-based permissions. |
Use platforms that support secure transmission, audit trails, and HIPAA Business Associate Agreements when required.
Confirm the vendor will sign a Business Associate Agreement (BAA) and provide an auditable certificate of completion and access logs.
Respond to individual access requests within 30 days (45 CFR §164.524(b)(2)).
Notify affected individuals without unreasonable delay, no later than 60 days after discovery (45 CFR §164.404).
Honor the expiration date specified; if none, treat with conservatively limited scope.
Revocation is effective upon receipt but does not undo disclosures already made.
Maintain authorizations for six years from creation or last effective date (45 CFR §164.530(j)).
| signNow | DocuSign | Adobe Sign | PandaDoc | HelloSign | |
|---|---|---|---|---|---|
| Starting Price | $8/user/mo | $15/user/mo | $14/user/mo | $19/user/mo | $15/user/mo |
| Free Trial | 7-day free trial, no credit card | Varies by vendor | Varies by vendor | Varies by vendor | Varies by vendor |
| Bulk Send | Yes | Yes | Yes | Yes | No |
| Audit Trail | Yes | Yes | Yes | Yes | Yes |
| HIPAA Compliant | Yes | Yes | Yes | No | No |
| Envelope Cap | No envelope cap | 100 envelopes/user/year | Varies | Varies | Varies |